Microsoft.Authorization/locks/delete
Microsoft.Authorization/locks/delete
Event
Removes a specific CanNotDelete or ReadOnly lock. Locks govern control-plane operations, not all data-plane activity. Parent locks can still apply after a child lock is removed. Lock deletion does not itself delete a protected resource or grant permission to do so.
Security Context
Unauthorized removal may prepare destructive activity (contextual T1485). Approved maintenance also removes locks. Risk depends on the actual lock level, inherited locks, permissions, and subsequent operations; the lock’s name is not proof of its settings.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Authorization/locks/delete. Inspect status/subStatus and related records; an accepted asynchronous request is not final resource-state evidence. Request and response bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
resourceId | Deleted lock and its scope. |
caller, status | Actor and outcome; recover the previous lock level separately. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Recover the lock’s previous level and maintenance approval.
- Check inherited locks, resource policies, and the actor’s effective permissions after removal.
- Correlate resource changes/deletions and actual impact; this record alone is not data destruction.
Sample Event
Synthetic scenario. The sample deletes a resource-group lock named prod-cannotdelete. Its prior level and remaining protections are not present in the event.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Authorization/locks/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Authorization/locks/prod-cannotdelete" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000001111000", "description": "", "eventDataId": "90000000-0000-4000-8000-000001111001", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T20:14:08.7172948Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000001111010", "operationName": { "value": "Microsoft.Authorization/locks/delete", "localizedValue": "Delete management lock" }, "resourceGroupName": "rg-fantasticlogs-prod", "resourceProviderName": { "value": "Microsoft.Authorization", "localizedValue": "Microsoft.Authorization" }, "resourceType": { "value": "Microsoft.Authorization/locks", "localizedValue": "Microsoft.Authorization/locks" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Authorization/locks/prod-cannotdelete", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T20:14:09.2018844Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Authorization/locks/prod-cannotdelete", "message": "Microsoft.Authorization/locks/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000001111011", "clientIpAddress": "203.0.113.66", "method": "DELETE", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Authorization/locks/prod-cannotdelete?api-version=2020-05-01" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...